AI cybersecurity threats surge as prompt‑injection attacks and rival tools proliferate
Experts warn that artificial‑intelligence models are becoming a central weapon in cyber‑conflict. Deloitte’s Nitin Mittal highlighted the geopolitical stakes of relying on a single AI model and urged diversified, sovereign‑AI strategies. Prompt‑injection attacks have exploded – CrowdStrike’s 2026 Global Threat Report recorded attacks on more than 90 organisations in 2025, with lateral‑movement times dropping to under 30 seconds. The technique manipulates large‑language models to steal credentials or cryptocurrency, as illustrated by the EchoLeak exploit that forced Microsoft Copilot to exfiltrate files.
Anthropic’s Claude Mythos, marketed for vulnerability discovery, can locate critical software flaws far faster than traditional methods, raising concerns that attackers could compress exploit timelines. Chinese firms have released comparable capabilities: Zhipu AI’s open‑weight GLM‑5.2 and 360 Security’s Tulongfeng tool claim performance on par with Mythos in detecting software vulnerabilities. Independent tests show GLM‑5.2 matching or surpassing US frontier models on specific security tasks while costing far less per bug.
Governments are responding. India’s CERT‑In directed agencies to avoid unapproved external AI platforms and strengthen multi‑factor authentication. The United States issued an executive order mandating a public‑private AI‑cybersecurity clearinghouse and limiting access to advanced models. Chinese officials argue that open‑weight models counterbalance U.S. export controls and stress strategic importance of domestic AI‑driven cyber tools.
Overall, the convergence of faster AI‑enabled attack methods and rival defensive tools is reshaping the cyber‑risk landscape for enterprises, critical infrastructure, and national security.